Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21737-1

Опубликовано: 02 сент. 2026
Источник: suse-cvrf

Описание

Security update for openexr

This update for openexr fixes the following issues:

  • CVE-2026-59183: unmapped memory access leading to crash due to int32_t multiplication overflow in unpack_sample_table() when decoding a crafted deep tiled EXR file (bsc#1276428).
  • CVE-2026-59184: out-of-bounds or use-after-free writes when processing a crafted EXR with a nonzero dataWindow.min (bsc#1276849).
  • CVE-2026-59186: heap out-of-bounds write on 32-bit/ILP32 builds when a crafted tiled EXR is read through the public TiledRgbaInputFile RGBA API (bsc#1276850).
  • CVE-2026-59189: heap out-of-bounds read when processing a deep image that has a non-zero dataWindow origin (bsc#1276855).
  • CVE-2026-59981: heap out-of-bounds read when procesing a deep image that has a non-zero dataWindow origin (bsc#1276862).
  • CVE-2026-59982: out-of-bounds pointer access when processing a crafted deep EXR that has a non-zero dataWindow origin (bsc#1276853).
  • CVE-2026-59983: out-of-bounds read in ILP32 builds when processing a crafted uncompressed deep-tile EXR (bsc#1276856).
  • CVE-2026-59984: out-of-bounds write in ILP32 builds when processing a crafted B44-compressed scanline EXR (bsc#1276857).
  • CVE-2026-59985: out-of-bounds read in ILP32 builds when processing a crafted RLE-compressed EXR (bsc#1276858).
  • CVE-2026-61555: undefined behavior when processing a crafted EXR with an empty multiView header attribute (bsc#1276859).
  • CVE-2026-68515: heap out-of-bounds write in exrmultiview when combining two specially crafted, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling (bsc#1276848).

Список пакетов

openSUSE Leap 16.0
libIex-3_2-31-3.2.2-160000.10.1
libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
libIlmThread-3_2-31-3.2.2-160000.10.1
libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1
libOpenEXR-3_2-31-3.2.2-160000.10.1
libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.10.1
libOpenEXRCore-3_2-31-3.2.2-160000.10.1
libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.10.1
libOpenEXRUtil-3_2-31-3.2.2-160000.10.1
libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.10.1
openexr-3.2.2-160000.10.1
openexr-devel-3.2.2-160000.10.1
openexr-doc-3.2.2-160000.10.1

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerability is reached when a crafted uncompressed deep-tile EXR causes the sample-count table size calculation in OpenEXRCore decoding.c to wrap before unpack_sample_table() iterates over the full attacker-controlled tile dimensions, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds write. When a crafted B44-compressed scanline EXR causes the logical scratch size to truncate before allocation and uncompress_b44_impl() writes using the attacker-controlled channel width, allowing denial of service and memory corruption. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки

Описание

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Затронутые продукты
openSUSE Leap 16.0:libIex-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-3.2.2-160000.10.1
openSUSE Leap 16.0:libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1

Ссылки
Уязвимость openSUSE-SU-2026:21737-1